ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

Microsoft takes Passport to Washington

Joe Wilcox and Stefanie Olsen, ZDNN GameSpot Europe

Published: 23 Aug 2001 08:48 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft on Wednesday descended on the nation's capital, trying to quell concerns its Passport authentication service poses a threat to consumers' privacy or security.

The company is here at the behest of the Center for Democracy & Technology (CDT), a consumer advocacy group that wishes to hear directly from the software maker on its plans, said Adam Sohn, Microsoft's manager for .Net platform strategy. The software giant may use the opportunity to talk with other groups or even some legislators. But Sohn, who spoke with this publication late Tuesday, said he did not know the day's itinerary.

Microsoft may have a lot of ground to cover. Last week, nearly 15 privacy and consumer groups amended a 26 July complaint filed with the Federal Trade Commission charging that Microsoft by offering Passport and associated services is engaging in unfair and deceptive trade practices in violation of Section 5 of the FTC act.

Passport is Microsoft's online authentication system, using a single sign-in to access multiple Web services. The idea behind Passport is simple: one secure ID and password rather than the many needed to access the wide range of Web sites and services consumers use every day. Microsoft uses Passport authentication for its MSN Messenger and Hotmail email services, Microsoft Developer Network online access, and Microsoft Reader e-book purchases, among other product and service offerings.

Passport also is the authentication for HailStorm, which has been billed as a way for subscribers to access their email, personal contact list, schedule and other Web services -- such as shopping, banking and entertainment -- through a variety of devices, such as PCs, cell phones and handhelds, from any location. HailStorm is part of Microsoft's forthcoming .Net software-as-a-service strategy.

But the privacy groups have questioned whether Passport collects too much information and lacks the basic security features required to protect basic information. Some industry analysts, however, question the validity of those claims.

"There's nothing I've seen in how Passport collects information that's any different from other Web sites," said Guernsey Research analyst Chris LeTocq.

The groups, which include the Electronic Privacy Information Center (EPIC) and Junkbusters, faulted Microsoft for collecting, among other things, e-mail addresses during the Passport sign-up process.

But this collecting of email addresses is "commonplace" on the Web, LeTocq said.

For its part, the CDT wants to get information directly from Microsoft rather than relying on third parties.

"There is a lot of discussion among security experts and privacy groups about Passport, HailStorm, Windows XP and where it's headed," Schwartz said. "We just wanted to get a briefing on the practical aside and ask some of the questions directly to Microsoft. That's the way we work. We like to talk to the company whenever an issue like this arises, work on some of the details and see where they're headed."

The CDT has gathered a number of local privacy and security experts for the Microsoft meeting. Schwartz said that at least in the CDT's briefing, no legislators would be present, nor representatives from the groups that filed the FTC complaints.

The CDT's stated mission "is to develop and implement public policies to protect and advance individual liberty and democratic values in new digital media," according to the organisation's Web site.

Sohn said Microsoft's objectives for the Passport briefings are clear: "To set the record on stuff that is out there and is misrepresenting our intent. We want to give the future of where we're going, both in the near term with technologies like Passport and longer term with stuff like .Net and HailStorm."

Sohn emphasised that Microsoft is "very concerned about privacy. And we want to have a dialogue where we're at and where we are going forward."

Still, controversy over Passport could hound Microsoft, despite recent changes designed to beef up privacy.

Several key features of Windows XP require a Passport account, causing some privacy groups, competitors and even trustbusters to cry foul. Windows Messenger -- Microsoft's communications console delivering instant messaging and videoconferencing, among other features -- uses Passport authentication. This has raised concerns from privacy groups and others that Microsoft plans to use Windows XP as a mechanism to drive new Passport sign-ups.

But Brian Arbogast, vice president of Microsoft's personal services and devices group, dismisses this. "In no way is Passport required to use Windows XP," he said.

Only communications features such as instant messaging and videoconferencing require Passport, Arbogast said. "Those systems only work unless you have the concept of an authentication system. There needs to be a way to know users are who they say they are."

One of Passport's greatest security weaknesses may be the single sign-on process, analysts said. The single point of entry could also be a single point of failure. Since the ID is always an email address, someone looking to break into an account might easily obtain half the information needed to do so.

"There is plenty of good password-cracking software out there," LeTocq said.

Microsoft is addressing this by offering additional security features for partner Web sites, such as banks, asking for additional information or a four-digit PIN (personal identification number) as a second level of authentication.

See the Surveillance News Section for the latest headlines.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Microsoft forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
27 out of 64 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

.NET 2.0 Developer - ASP.NET, C#, Web Services - Home Working

Huxley Associates' Client based in the Slough area is currently recruiting for a Senior PHP Developer to join them on a contract basis. You will need ...

Architect - Web Services - Finance - London - Comp

A Web Services Architect with a broader Enterprise Content Management responsibilty is required for a leading Financial Body. This role requires ...

Java Developer - Web Services - Axis

Huxley Associates reputable city based underwriting client have the requirement for a Java Developer with Web Services and Axis experience. You will ...

Discussions

keithmv keithmv

Password Deadlock

Saturday 26 July 2008, 12:02 PM

2 comments

Blog Posts

Avatar geek

Gateway 450SX4 Laptop Computer

Saturday 26 July 2008, 4:46 AM

0 comments
Avatar geek

Windows XP

Saturday 26 July 2008, 4:41 AM

0 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme